Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Subway Surfers Official

afanpbdmlbfmjbfofhbaaafcpmjfgfem
Risk Score
4.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 6,000
Rating 3.4
Last updated 2026-06-17 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@gameograf.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack and install URL hijack are active monetization/tracking patterns.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • External JS loaded from gameograf.com enables remote code update without store review.
  • No developer name on listing; manifest uses placeholder strings (__MSG_appName__).
  • Verified publisher discount limited: generic privacy policy points to non-developer domain.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; uninstall_url_target is null but flag is true.
  • install_url_hijack crx onInstalled opens external URL; install_url_target is null but flag is true.
  • privacy_policy_generic store Policy URL is Google's own account policy; fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
  • js_external_hosts crx Extension references gameograf.com as external JS host — remote code capability outside CWS review.
  • no_developer_name store developer_name is empty string; manifest uses __MSG_appName__ placeholder.
  • verified_publisher store Listing carries verified_publisher=true, but discount capped due to generic unscoped privacy policy.
  • low_rating store Rating 3.4; install count only 6,000 for an 'Official' game extension claim.
  • csp_absent crx content_security_policy is null; csp_present=false on MV3 extension with external JS host.

Permissions Breakdown

  • uninstall_url_hijack high Extension sets an uninstall URL to a third-party destination, a monetization/tracking signal.
  • install_url_hijack high Extension opens a URL on install via onInstalled, a known traffic-monetization pattern.
  • js_external_hosts (gameograf.com) medium Extension loads JS from developer-controlled external host; remote code execution risk.

Pillar Scores

Permissions4.00
Reputation5.50
Network2.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality1.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 09:41
Listing SHA 5ee7cfb998bf…
Force block — not fired
Score recovered no
Elapsed